started · updated
Cisco and Citrix issue urgent patches for critical security vulnerabilities
Cisco has released a hardening update for Crosswork to address several internally discovered vulnerabilities. A critical flaw, identified as CVE-2026-20030, involves improper handling of special characters in SQL commands, creating a risk for SQL injection. Additionally, Cisco reported critical vulnerabilities in Crosswork and Secure Workload that could lead to remote code execution, authentication bypass, or path traversal.
Separately, Citrix has issued warnings regarding two vulnerabilities in NetScaler Gateway and NetScaler ADC. The more severe flaw, CVE-2026-19490, allows unauthenticated remote attackers to bypass authentication under specific configurations involving SAML actions. A second high-severity vulnerability, CVE-2026-19489, is a buffer overflow that could enable remote denial-of-service attacks when the SIP Application Layer Gateway is active in certain NAT configurations.
Citrix recommends that administrators update to NetScaler ADC and NetScaler Gateway versions 14.1-73.32 or newer, or 13.1-63.21 or newer, depending on the specific environment. While there are currently no reports of these Citrix vulnerabilities being actively exploited, the company notes that previous NetScaler flaws were exploited shortly after disclosure.
Entities
Cisco · Citrix · Crosswork · NetScaler · Secure Workload